Incidents and alerts
Reduce alert fatigue and better manage incident response
Collect, enrich, prioritize, and respond to incidents in a more efficient and effective way. From customer escalations to security events or data breaches, we've got you covered.
Featured stories

Alert users of JupiterOne issues associated to their accountSend users all alerts and problems associated with their account. This can be triggered by a Slack command or a scheduled message to highlight info to users.Tools: JupiterOne, Slack

Escalate alerts which users have not responded toCheck with a user to see if they recognize an alert. If no response is received within 5 minutes, escalate the issue. If the user responds within 5 minutes, no escalation is required.

Create & manage incident communications with Slack and Jira
This Story allows teams to create and manage incident communication directly through Slack. It can create Slack channels for communications, and sync conversation backups to a Jira ticket for long-term preservation.
Tools
Created by
Rosie Ellison
Loading story...
How it works
Instantly import stories to your tenant where you can adapt them to meet your unique business requirements.
Learners welcome
Step through beginner to advanced topics as you explore our tailored courses on Tines Stories University
Enrich files and URLs with PolySwarmEnrich file hash and URL indicators with PolySwarm threat intelligence as a standalone flow or attached to a Tines Case, with optional URL detonation for the latest threat data.Tools: PolySwarm
Authorize distributed Slack apps and store OAuth tokens using pagesAutomate the OAuth 2.0 authorization flow for distributed Slack apps, collecting bot and user tokens and storing them automatically as Tines credentials for use in other workflows.Tools: Slack, Tines
Create Tines Cases for Netskope DLP Incidents using the AI Agent actionRetrieve DLP incidents from Netskope and generate individual Tines Cases using the AI Agent action.Tools: Netskope
Sync Insider Threat Matrix records and attach to CasesRetrieve categories from the Insider Threat Matrix website, sync them into a Tines Stories record type, and let analysts attach or detach matching records from Cases.

Generate a branching text adventure using the AI Agent actionGenerate an interactive, branching adventure story game with an AI Agent action and illustrate each choice with images.
Benchmark AI models for performance in TinesBenchmark AI models' agentic performance across extraction and tool-use tasks, then automatically grade each model to identify which are suitable for Tines AI functionality.
Enrich files and URLs with PolySwarmEnrich file hash and URL indicators with PolySwarm threat intelligence as a standalone flow or attached to a Tines Case, with optional URL detonation for the latest threat data.Tools: PolySwarm
Create Tines Records from a CSV uploadUse a Tines Page to upload a CSV file and automatically create a Tines record type and records from its rows, enabling quick self-service data import.Tools: TinesMitigate alert fatigue with these best practices

Send a prompt to a Slack channel or user & take actionThis Story allows you to send a prompt to a Slack user or channel, take actions based on the response, and transfer information from the Story run that triggered the prompt.Tools: Slack

Tracking state in Tines ResourcesTines Resources are helpful for keeping track of information across Stories, Events, and Story Runs. In this example, we'll keep track of the number of times a user has been seen in a Resource.How Snowflake saves 10 hours daily
Snowflake's incident response team reduced manual alert correlation by 91.4%, saving ~10 hours daily in manual tasks, and built a internal case management system powered by Tines and Snowflake..
Find more stories
Incidents and alerts come from all directions, check out these similar use cases.
Submit your story
We’d love to hear your ideas or see what you’ve created.